Working Exploit Released for AnyDesk Linux Flaw That Grants Root Access Before Anyone Approves a Connection
Security researchers have published a full working exploit, named AnyPwn, for a serious flaw in AnyDesk on Linux. The bug is a heap buffer overflow in the remote desktop tool's session protocol. It lets an attacker run commands with root access before anyone approves the connection. The code appeared on GitHub on October 8.
AnyDesk fixed the issue in version 8.0.3 in June, but its changelog described it only as "fixed a bug that could lead to a crash". No CVE has been assigned as of October 9, and there is no formal security advisory. The published exploit works only over direct TCP connections on port 7070, and it is probabilistic: if the memory layout does not line up, the service crashes instead of running the attacker's command. The offsets target AnyDesk Linux 8.0.2, so other builds would need different values. Researchers imply earlier versions such as 8.0.1 may share the flaw, but this is unconfirmed.
AnyDesk has said the problem is limited to direct connections on Linux, and that Windows and macOS are not affected. The researchers say the same vulnerable code can be reached through AnyDesk's relay servers, which they validated with a Frida instrumentation trigger, but they did not demonstrate a full exploit over relays. That question remains unresolved. Administrators should update to at least 8.0.3 (the latest release is 8.1.0). If that is not possible straight away, restrict access to TCP port 7070.